> For the complete documentation index, see [llms.txt](https://docs.1kosmos.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.1kosmos.com/authentication/windows-workstation-mfa.md).

# Windows Workstation MFA

- [Overview](https://docs.1kosmos.com/authentication/windows-workstation-mfa/overview.md): The Windows Workstation MFA Agent adds multi-factor and passwordless authentication to the Windows login experience, controlled centrally from AdminX Portal.
- [System Requirements](https://docs.1kosmos.com/authentication/windows-workstation-mfa/system-requirements.md): This page lists the supported operating systems and minimum hardware specifications for the Linux host on which the 1Kosmos PAM will be installed.
- [Installation](https://docs.1kosmos.com/authentication/windows-workstation-mfa/installation.md): The Windows Workstation MFA Agent supports two installer formats. Choose the right one for your environment before proceeding, switching formats later requires a full uninstall and reinstall.
- [Install using MSI](https://docs.1kosmos.com/authentication/windows-workstation-mfa/installation/install-using-msi.md): The MSI installer is the recommended method for all new deployments. It supports silent installation, SCCM, Intune, and GPO deployment natively.
- [Install using EXE (Legacy)](https://docs.1kosmos.com/authentication/windows-workstation-mfa/installation/install-using-exe-legacy.md): The EXE installer is supported for existing deployments and manual installations. For all new deployments, use the MSI installer instead.
- [Post-installation Verification](https://docs.1kosmos.com/authentication/windows-workstation-mfa/installation/post-installation-verification.md): After installing the agent, complete these steps to confirm the Credential Provider is active and authentication is working before rolling out to users.
- [Authentication Methods](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods.md): The Windows Workstation MFA Agent supports multiple authentication methods. The method presented to a user at login is determined by the Adaptive Auth Journey configured for them in AdminX.
- [Password + OTP](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/password-+-otp.md): Users authenticate by entering their Active Directory password followed by a one-time passcode. This is the most common MFA configuration for organisations transitioning away from password-only login.
- [Push Notification](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/push-notification.md): Users receive an approval request on the 1Kosmos mobile app. From v2.0.4.0, a Number Challenge option is available to protect against push bombing attacks.
- [QR code](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/qr-code.md): Users scan a QR code displayed on the Windows login screen using the 1Kosmos mobile app. No password is required when QR is configured as the sole authentication method.
- [LiveID Selfie](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/liveid-selfie.md): Configure LiveID Selfie with Push Notification for Windows login in 1Kosmos. Authenticate using facial biometrics and 1Kosmos app approval.
- [1Key Biometric](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/1key-biometric.md): Users authenticate using a FIDO2 hardware security key. 1Kosmos supports both single-user keys and multi-user biometric keys (1Key Desktop, which supports up to 3 enrolled users per key).
- [SMS, Email, Voice, OTP](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/sms-email-voice-otp.md): Available from v2.0.6.0. Users receive a one-time passcode via SMS, email, or voice call. No mobile app installation is required.
- [Behavior Authentication](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/behavior-authentication.md): Users authenticate by typing a displayed phrase (typing biometrics) followed by a PIN. No mobile app or hardware key required. Supports offline authentication via cached PIN.
- [Fallback Authentication](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/fallback-authentication.md): Configure a secure fallback authentication method for Windows login so users can regain access with a Helpdesk-issued one-time passcode when their primary method fails.
- [Run As & UAC](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/run-as-and-uac.md): 1Kosmos Credential Provider intercepts Run As and UAC elevation prompts, requiring MFA before elevated access is granted. From v2.0.7.0, passwordless authentication is supported for these scenarios.
- [Deployment Scenarios](https://docs.1kosmos.com/authentication/windows-workstation-mfa/deployment-scenarios.md): 1Kosmos Credential Provider intercepts Run As and UAC elevation prompts, requiring MFA before elevated access is granted. From v2.0.7.0, passwordless authentication is supported for these scenarios.
- [Standard Domain Joined Workstations](https://docs.1kosmos.com/authentication/windows-workstation-mfa/deployment-scenarios/standard-domain-joined-workstations.md): Baseline deployment scenario for 1Kosmos Windows Workstation MFA Agent. Covers Active Directory domain-joined machines with full network connectivity to 1Kosmos tenant.
- [RDP](https://docs.1kosmos.com/authentication/windows-workstation-mfa/deployment-scenarios/rdp.md): 1Kosmos Credential Provider supports MFA enforcement for both incoming and outgoing Remote Desktop Protocol (RDP) sessions.
- [Shared Workstations](https://docs.1kosmos.com/authentication/windows-workstation-mfa/deployment-scenarios/shared-workstations.md): Shared workstation environments allow multiple users to authenticate on the same physical machine using their individual identities, then access shared or privileged accounts managed by CyberArk.
- [Offline Scenario](https://docs.1kosmos.com/authentication/windows-workstation-mfa/deployment-scenarios/offline-scenario.md): Securely log into your Windows workstation even without internet access or when the 1Kosmos cloud is unreachable, using offline authentication methods supported by the 1Kosmos Credential Provider.
- [Entra Joined Workstations](https://docs.1kosmos.com/authentication/windows-workstation-mfa/deployment-scenarios/entra-joined-workstations.md): Support for Microsoft Entra ID joined machines (formerly Azure AD joined) is on 1Kosmos product roadmap. This page will be updated when the feature is available.
- [Uninstall](https://docs.1kosmos.com/authentication/windows-workstation-mfa/uninstall.md): 1Kosmos Windows Workstation MFA Agent can be uninstalled using either the MSI or EXE method, depending on how it was originally installed. A reboot is required after uninstall to remove the machine.
- [Uninstall MSI](https://docs.1kosmos.com/authentication/windows-workstation-mfa/uninstall/uninstall-msi.md): Uninstalling 1Kosmos Windows Workstation MFA Agent via MSI package. Supports both silent (command-line) and UI-guided removal.
- [Uninstall EXE](https://docs.1kosmos.com/authentication/windows-workstation-mfa/uninstall/uninstall-exe.md): Uninstalling 1Kosmos Windows Workstation MFA Agent when it was installed using EXE installer package. Supports both silent (command-line) and UI-guided removal.
- [Troubleshooting & Support](https://docs.1kosmos.com/authentication/windows-workstation-mfa/troubleshooting-and-support.md): This page covers cross-cutting issues with 1Kosmos Windows Workstation MFA Agent, installation failures, Credential Provider service problems, log collection, and connectivity diagnostics.
- [Release Notes for Windows Workstation MFA](https://docs.1kosmos.com/authentication/windows-workstation-mfa/release-notes-for-windows-workstation-mfa.md): Release history for the 1Kosmos Workstation Login Credential Provider for Windows
- [FAQs](https://docs.1kosmos.com/authentication/windows-workstation-mfa/faqs.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.1kosmos.com/authentication/windows-workstation-mfa.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
